XML-RPC Interface Vulnerability in WatchGuard Fireware
CVE-2017-14616

7.5HIGH

Key Information:

Vendor
Watchguard
Status
Vendor
CVE Published:
20 September 2017

Summary

A Denial of Service vulnerability exists in WatchGuard Fireware prior to version 12.0, where an empty member element in an XML message sent to the XML-RPC interface can cause the wgagent to crash. This results in the immediate logout of any active users and disrupts the UI management of the device, making it impossible to manage the device effectively. Continuous failed login attempts exacerbate the issue, leading to a complete denial of access.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.